
CVE-2020-37022 OpenZ ERP 3.6.60 contains a persistent cross-site scripting vulnerability in the Employee module's name and description parameters. Attackers can inject malicious scr… https://www.cve.org/CVERecord?id=CVE-2020-37022
Post summary
This advisory describes a persistent XSS flaw (CVE-2020-37022) in OpenZ ERP 3.6.60 that targets the Employee module's name and description fields.
